QID 591118

Date Published: 2022-10-14

QID 591118: Siemens SIMATIC S7-1500 CPU family Multiple Vulnerabilities (ICSA-14-073-01,SSA-456423)

AFFECTED PRODUCTS
The following SIMATIC S7-1500 versions are affected:SIMATIC S7-1500 CPU family, all versions older than V1.5

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

The multiple vulnerabilities discovered in the SIMATIC S7-1500 CPU firmware may allow attackers to perform denial-of-service (DoS) attacks with specially crafted HTTP(S), ISO-TSAP, or Profinet network packets. The integrated web server may also be vulnerable to cross-site request forgery (CSRF), cross-site scripting (XSS), header injection, and open redirect attacks as well as privilege escalation. The vulnerabilities could be exploited over the network without authentication.

  • CVSS V3 rated as Low - 0 severity.
  • CVSS V2 rated as Critical - 8.3 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-14-073-01 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-14-073-01 URL Logo www.cisa.gov/uscert/ics/advisories/ICSA-14-073-01
    ssa-456423 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-456423.pdf